Cyber Resilience Act resources
Page 10 of 14
Showing resources 136 to 150 of 202.
How Downstream Manufacturers Should Handle Open Source Components
Learn how downstream manufacturers should handle open-source components under the Cyber Resilience Act, including due diligence, component vulnerabilities, upstream notification, remediation, SBOMs and security attestations.
READ GUIDE Open source software and the CRA / 11CRA Documentation for Open Source Components
Understand what CRA documentation manufacturers should maintain for open-source components, including SBOMs, architecture relationships, cybersecurity risk assessments, vulnerabilities, disclosure policies and secure update processes.
READ GUIDE Secure product development / 12Managing Secrets and Credentials in CRA-Covered Products
Learn how secrets and credentials should be managed throughout CRA product development, including provisioning, storage, uniqueness, rotation, revocation, reset, build secrets and release evidence.
READ GUIDE Secure product development / 13Secure Configuration Management Under the CRA
Learn how to manage secure product configuration throughout the CRA development lifecycle, including baselines, change control, configuration drift, variants, release verification and configuration evidence.
READ GUIDE Secure product development / 14Authentication and Access-Control Design Under the CRA
Learn how authentication and access-control architecture can support CRA requirements, including identity models, authorisation, least privilege, administrative access, service identities, recovery and access-control testing.
READ GUIDE Technical documentation / 09CRA Product Architecture Documentation
Learn how to document product and system architecture for Cyber Resilience Act technical documentation, including software components, interfaces, data flows, trust boundaries, dependencies, security functions and version-specific architecture evidence.
READ GUIDE Technical documentation / 10CRA Security Design Documentation
Learn how to document security design decisions for Cyber Resilience Act technical documentation, including security requirements, architecture controls, trust boundaries, secure defaults, cryptography, resilience, updates and Annex I traceability.
READ GUIDE Technical documentation / 11Documenting Security Test Results
Learn how to document Cyber Resilience Act security test results for Annex VII technical documentation, including test scope, product version, environment, Annex I mapping, methods, findings, remediation and retesting.
READ GUIDE Open source software and the CRA / 12Donations, Sponsorship and Commercial Activity Under the CRA
Understand how donations, sponsorship, grants, corporate contributions and recurring financial assistance affect the Cyber Resilience Act commercial-activity analysis for free and open-source software.
READ GUIDE Open source software and the CRA / 13Preparing an Open Source Project for CRA-Related Requests
Learn how an open-source project can prepare for Cyber Resilience Act related requests from market surveillance authorities, downstream manufacturers and security researchers without assuming manufacturer obligations that do not apply.
READ GUIDE Secure product development / 15Cryptography and the Cyber Resilience Act
Understand how cryptographic design supports Cyber Resilience Act requirements, including confidentiality, integrity, update verification, algorithm selection, key management, certificates, randomness and cryptographic agility.
READ GUIDE Secure product development / 16Designing Products for Secure Updating
Learn how to design a CRA-ready security update architecture covering update authenticity, integrity, signing keys, safe installation, automatic updating, rollback, recovery, version targeting and secure distribution.
READ GUIDE Secure product development / 17How to Build a CRA-Compliant Secure Development Lifecycle
A practical framework for building a CRA-aligned secure development lifecycle covering cybersecurity risk assessment, requirements, architecture, coding, security reviews, testing, release, maintenance and compliance evidence.
READ GUIDE Technical documentation / 12Documenting Vulnerability Handling Processes
Learn how to document Cyber Resilience Act vulnerability handling processes for Annex VII technical documentation, including SBOM management, vulnerability intake, coordinated disclosure, remediation, security updates and evidence.
READ GUIDE Technical documentation / 13Maintaining Technical Documentation After Product Changes
Learn how Cyber Resilience Act technical documentation should be maintained after software, architecture, production, dependency, security-control and conformity-reference changes.
READ GUIDE